From: <dai...@us...> - 2014-03-14 06:36:01
|
Revision: 6604 http://sourceforge.net/p/web-erp/reponame/6604 Author: daintree Date: 2014-03-14 06:35:58 +0000 (Fri, 14 Mar 2014) Log Message: ----------- what happens if we do this? Modified Paths: -------------- trunk/includes/ConnectDB_mysql.inc trunk/includes/ConnectDB_mysqli.inc trunk/install/index.php Modified: trunk/includes/ConnectDB_mysql.inc =================================================================== --- trunk/includes/ConnectDB_mysql.inc 2014-03-12 05:53:03 UTC (rev 6603) +++ trunk/includes/ConnectDB_mysql.inc 2014-03-14 06:35:58 UTC (rev 6604) @@ -164,7 +164,7 @@ } function DB_escape_string($String){ - return mysql_real_escape_string(htmlspecialchars($String, ENT_COMPAT, 'utf-8', false)); + return mysql_real_escape_string($String); } function DB_show_tables(&$Conn){ Modified: trunk/includes/ConnectDB_mysqli.inc =================================================================== --- trunk/includes/ConnectDB_mysqli.inc 2014-03-12 05:53:03 UTC (rev 6603) +++ trunk/includes/ConnectDB_mysqli.inc 2014-03-14 06:35:58 UTC (rev 6604) @@ -181,7 +181,7 @@ function DB_escape_string($String){ global $db; - return mysqli_real_escape_string($db, htmlspecialchars($String, ENT_COMPAT,'utf-8', false)); + return mysqli_real_escape_string($db, $String); } function DB_show_tables(&$Conn){ Modified: trunk/install/index.php =================================================================== --- trunk/install/index.php 2014-03-12 05:53:03 UTC (rev 6603) +++ trunk/install/index.php 2014-03-14 06:35:58 UTC (rev 6604) @@ -384,7 +384,7 @@ $msg .= "if (\$RootPath == '/' OR \$RootPath == '\\\') {\n"; $msg .= " \$RootPath = '';\n"; $msg .= "}\n"; - $msg .= "error_reporting(E_ALL && ~E_NOTICE && E_WARNING);\n"; + $msg .= "error_reporting(E_ALL && ~E_NOTICE && ~E_WARNING);\n"; $msg .= "//Installed companies \n"; foreach ($CompanyList as $k=>$compinfo) { |